have I still got braviax?? Maybe???

Discussion in 'Malware Help (A Specialist Will Reply)' started by honestandy, Mar 4, 2008.

  1. honestandy

    honestandy Private E-2

    hey guys,

    I have recently ended up with braviax on my PC and I think its now gone (well at least all the signs have gone like the toolbar bubble and no signs of winreactivator or whatever it was called :eek:) but I have been left with a few problems which I think are registry related but not really sure, they are:

    Every time I start my PC it tells me it has just recovered from a major problem!

    But the major thing is when I try to do a few things the screen goes BLUE and I get the error message "***STOP*** 0X 0000008E (0XC000005, 0X 00200020, 0X B89778, 0X 000000000) this happens everytime I try to use the volume control on the toolbar.

    Andy ideas guys? is this because of braviax?? its reallly problematic, what do I need to do?

    Any help truly appreciated

    thanks
    andy
     
  2. Lev

    Lev MajorGeek

  3. honestandy

    honestandy Private E-2

    still got issues - logs here

    hey guys,

    I have the requested logs took ages due to super anti kept crashing at the end!! I have problems when trying to use the sound icon on the toolbar the screen goes blue with error message "***STOP*** 0X 0000008E 90XC000005 0X0020020 0XB89778 0X000000000.

    It seems all the signs of braviax have gone but I keep getting this blue screen and the pc is running slow, has braviax gone, the computer was running great before I got braviax and now keep getting blue screened and going slow.

    Any hep truly appreciated :)
    thanks
    andy
     

    Attached Files:

  4. honestandy

    honestandy Private E-2

    even worse now, no connection

    hey guys,

    I have attached requested logs, I understand you guys are busy and havent had time to look yet, but I thought Id up date you.

    I now cant connect to the internet through forefox or IE, my laptop says that my wireless is now connected as usual but I cant get anything to connect like email or internet, the signs of braviax are gone but still keep getting the blue screen as per previous post when I try to use the volume control.

    My wireless equipment are working fine as this message is being sent of another pc connected via it.

    Things seem to be worse now with the blue screen and more important no internet, any suggestions.

    thanks for your time
    andy
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: even worse now, no connection

    You have a load of malware.


    Is your copy of Spyware Doctor a paid version or a free trial. If free, uninstall it now.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 4
    Java(TM) 6 Update 2
    Java(TM) 6 Update 3
    Java(TM) SE Runtime Environment 6 Update 1

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [4oD] "C:\Program Files\Kontiki\KHost.exe" -all
    O4 - HKCU\..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all
    O4 - HKCU\..\Run: [braviax] C:\WINDOWS\system32\braviax.exe
    O4 - HKCU\..\Run: [nvcoi] C:\Program Files\nvcoi\nvcoi.exe
    O9 - Extra button: WH GBP Casino - {37236812-C1A2-4529-A9CE-CFE04E3DF08A} - C:\Documents and Settings\Andy Hart\Desktop\WH GBP Casino.lnk (file missing)
    O9 - Extra 'Tools' menuitem: WH GBP Casino - {37236812-C1A2-4529-A9CE-CFE04E3DF08A} - C:\Documents and Settings\Andy Hart\Desktop\WH GBP Casino.lnk (file missing)
    O9 - Extra button: Email Extractor - {AFA7DB99-3E4D-4396-94F8-B0B135BCB472} - C:\Program%20Files\Tweak%20Marketing\Advanced%20Email%20Extractor\AeeMSIE.dll (file missing)
    O9 - Extra 'Tools' menuitem: Advanced Email Extractor - {AFA7DB99-3E4D-4396-94F8-B0B135BCB472} - C:\Program%20Files\Tweak%20Marketing\Advanced%20Email%20Extractor\AeeMSIE.dll (file missing)
    O9 - Extra button: InterCasino £££ - {03588886-5C50-4645-BD5D-F105F84417DE} - http://www.intercasino.co.uk/ (file missing) (HKCU)
    O9 - Extra 'Tools' menuitem: InterCasino £££ - {03588886-5C50-4645-BD5D-F105F84417DE} - http://www.intercasino.co.uk/ (file missing) (HKCU)
    O9 - Extra button: WH GBP Casino - {37236812-C1A2-4529-A9CE-CFE04E3DF08A} - http://www.williamhillcasino.com (file missing) (HKCU)
    O9 - Extra 'Tools' menuitem: WH GBP Casino - {37236812-C1A2-4529-A9CE-CFE04E3DF08A} - http://www.williamhillcasino.com (file missing) (HKCU)
    O16 - DPF: {F7EDBBEA-1AD2-4EBF-AA07-D453CC29EE65} (Flash Casino Helper Object) - https://flashcasino.ladbrokes.com/instant-play-en/FlashAX2.cab
    O20 - Winlogon Notify: qomkkij - qomkkij.dll (file missing)

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it :
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Administrator\Local Settings\Temp

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  6. honestandy

    honestandy Private E-2

    combofix problem

    i cant run combofix, I did as you said with the "cfscript" but when I drag it on to combofix.exe the window pops up but nothing happens, then when I do it again it says I cant rename it combofix.exe so I need to try another name. It just wont do anything when I drag it on top of the exe??

    Please help

    thanks
    andy
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: combofix problem

    Okay we will do this a different way. I'm assuming you have completed the other instructions prior to the part with ComboFix.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Administrator\Local Settings\Temp

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  8. honestandy

    honestandy Private E-2

    hey how are you guys?

    Ok I have done everything explained to me, and it looks to me as the problem is fixed!! :D I have no signs of braviax and my internet connects first time on wireless, so hopefully Im all clean?

    I have attached logs for you to confirm.

    Thank you so much for all your help :)
    andy

    One weird little problem Im having is when I start my laptop it asks me to select which system to start: windowns XP or the recovery console?? it never used to do that, is it normal, or can I change it back somehow?

    thanks
    again
     

    Attached Files:

  9. honestandy

    honestandy Private E-2

    looks like I spoke to soon, I now cant get connected once again and its running really slow!! aaaaaaarrrrrrhhhhh just when I thought it was all sorted.

    Pretty please put an end to my misery.

    anxiously waiting your reply
    andy
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Some new items appear to be in your logs. It is quite possible that inbetween the time you attach your new logs and then come back to work on a fix I give you that things have already changed on your PC. Any powerdown/reboot of your PC could cause new files to be created. Thus even the fix I will given below could be incomplete. From now on after you attach your logs, you must make sure that you do not power down or reboot your PC. If you are not in able to leave your PC running at the current time then do not even get the new logs to attach until you can leave it running.

    Please rename the ComboFix.exe file on your Desktop to cf.exe We will attempt to use this further down in this message.

    Now uninstall Speeditup Free 4.50F


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now. If you don't see certain lines, just continue.

    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O4 - HKCU\..\Run: [Search Defender] "C:\Program Files\Speeditup Free\SearchDefender.exe"
    O9 - Extra button: InterCasino £££ - {03588886-5C50-4645-BD5D-F105F84417DE} - C:\Documents and Settings\Andy Hart\Desktop\InterCasino £££.lnk (file missing)
    O9 - Extra 'Tools' menuitem: InterCasino £££ - {03588886-5C50-4645-BD5D-F105F84417DE} - C:\Documents and Settings\Andy Hart\Desktop\InterCasino £££.lnk (file missing)

    After clicking Fix, exit HJT.

    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop and that you have Renamed it to cf.exe but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as cf.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of cf.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  11. honestandy

    honestandy Private E-2

    No change, I have renamed combofix as you said, but when I drag the notepad file on to it the box pops up and then does nothing? I have left it for over an hour and still no change, I have no other windows open during that time.
    I did everything you asked prior to the combofix step.

    My computer is still the same no internet connection and running really slow :cry

    any suggestions? as to why combofix wont play ball?

    thanks
    andy
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please do the below so I can determine your current status. This malware appears to be changing at each reboot or power down.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs
    • C:\MGlogs.zip
    After attaching the above new log, DO NOT power down or reboot your PC. You must keep it running until I post a new fix. We will have to go back to using Avenger since you have something blocking you from using ComboFix.
     
  13. honestandy

    honestandy Private E-2

    hi,

    I have created the new logs file, and will now leave it switched on until I get your new reply with futher steps.

    thanks
    andy
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    After reboot look for all of the above files we had Avenger attempt to delete. If you still see them, delete them yourself.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
    Last edited: Mar 18, 2008
  15. honestandy

    honestandy Private E-2

    ok I have done everything as you said and my connection is back on, I then checked to try and delete the list of files if any got left behind but none of them did :)

    I have attached the logs and will leave my laptop switched on and not reboot or powerdown until you check my logs and give me the green light.

    huge thanks again
    andy
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're logs are basically clean! Just delete the below folder:
    C:\Documents and Settings\All Users\Application Data\Kontiki

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the /U, it must be there.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you run RenV.exe, you can delete it and the Log.txt file on your Desktop.
    9. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    10. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    11. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    12. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    13. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds